Junglewise Threat Intelligence

CVE-2015-1642: Microsoft Office Memory Corruption Vulnerability

CVE-2015-1642 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Office. Vendors: Microsoft.

Executive brief

Microsoft Office 2007, 2010, and 2013 contain a memory corruption vulnerability (specifically an out-of-bounds write) that allows remote attackers to execute arbitrary code. Exploitation occurs when a user opens a specially crafted document.

Affected products

  • Microsoft Office 2007 SP3
  • Microsoft Office 2010 SP2
  • Microsoft Office 2013 SP1

Timeline

  • 2015-08-11: disclosed: Initial publication of MS15-081 security bulletin.
  • 2015-08-11: patched: Microsoft released patches via MS15-081.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats